IP Library Granted Patent US 12,341,872
Granted Patent B2
US 12,341,872 · App. 16/620,241 · Granted Jun 24, 2025

Hardware security module management

Inventor: Joshua Daniel (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L9/0819H04L9/0643H04L9/3247H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,872
App. No.
16/620,241
Granted
Jun 24, 2025
Kind
B2
Abstract

A computer implemented method of a secure computing component to provide access to a cryptographic key, the key being associated with the secure component by a digitally signed record in a blockchain wherein the blockchain is accessible via a network and includes a plurality of records validated by miner computing components, the method including receiving a request from another secure computing component to associate the key with the other component, the request having associated identification information for a requester of the key; responsive to a verification of an entitlement of the requester, generating a new record for storage in the blockchain, the new record associating the key with the other component and being validated by the miner components; and further responsive to the verification, securely transferring the key to the other component so as to provide access to the key to the key requester via the other component.

Claims (32)

1. A computer implemented method of non-repudiatively transitioning management of a cryptographic key from a first hardware security module (HSM) to a second HSM, the cryptographic key being associated with the first HSM by a digitally signed record in a blockchain, the blockchain being accessible via a network and including a plurality of records validated by miner computing components, wherein the blockchain is not relied on for management or storage of the cryptographic key, the method comprising:

receiving a request from the second HSM to associate the cryptographic key with the second HSM, the request having associated identification information for a requester of the cryptographic key;

verifying an entitlement of the requester to the cryptographic key by the first HSM, wherein the entitlement of the requester is verified based on the identification information for the requester;

responsive to the verification by the first HSM, generating a new record for storage in the blockchain, the new record associating the cryptographic key with the second HSM and being validated by the miner components;

further responsive to the verification by the first HSM, securely and non-repudiatively transferring the cryptographic key from the first HSM to the second HSM;

verifying that the cryptographic key is associated with the second HSM in the blockchain; and

responsive to the verification that the cryptographic key is associated with the second HSM, transferring the cryptographic key from the second HSM to the requester of the cryptographic key.

2. The method of claim 1 , wherein the new record for storage in the blockchain includes a reference to an original record for the cryptographic key such that the new record supersedes the original record to associate the cryptographic key with the second HSM and to disassociate the cryptographic key from first HSM.

3. The method of claim 1 , wherein at least some of the miner computing components are hardware security modules (HSMs).

4. The method of claim 1 , wherein the blockchain is a distributed transactional database.

5. The method of claim 1 , wherein the miner components confirm a state of the blockchain by reaching a consensus as to the state of the blockchain based on a proof of work.

6. The method of claim 1 , further comprising:

further responsive to the verification of the entitlement of the requester, effecting a change to the second HSM for providing the cryptographic key, the change being relative to the resource cost of ownership of the cryptographic key.

7. A computer system comprising:

a processor and memory storing computer program code for non-repudiatively transitioning management of a cryptographic key from a first hardware security module (HSM) to a second HSM, the cryptographic key being associated with the first HSM by a digitally signed record in a blockchain, the blockchain being accessible via a network and including a plurality of records validated by miner computing components, wherein the blockchain is not relied on for management or storage of the cryptographic key, by:

receiving a request from the second HSM to associate the cryptographic key with the second HSM, the request having associated identification information for a requester of the cryptographic key;

verifying an entitlement of the requester to the cryptographic key by the first HSM, wherein the entitlement of the requester is verified based on the identification information for the requester;

responsive to the verification by the first HSM, generating a new record for storage in the blockchain, the new record associating the cryptographic key with the second HSM and being validated by the miner components;

further responsive to the verification by the first HSM, securely and non-repudiatively transferring the cryptographic key from the first HSM to the second HSM;

verifying that the cryptographic key is associated with the second HSM in the blockchain; and

responsive to the verification that the cryptographic key is associated with the second HSM, transferring the cryptographic key from the second HSM to the requester of the cryptographic key.

8. The computer system of claim 7 , wherein the processor and memory storing computer program code for the first HSM to provide access to the cryptographic key includes:

further responsive to the verification of the entitlement of the requester, effecting a change to the second HSM for providing the cryptographic key, the change being relative to the resource cost of ownership of the cryptographic key.

9. A non-transitory computer-readable storage medium storing a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to non-repudiatively transition management of a cryptographic key from a first hardware security module (HSM) to a second HSM, the cryptographic key being associated with the first HSM by a digitally signed record in a blockchain, the blockchain being accessible via a network and including a plurality of records validated by miner computing components, wherein the blockchain is not relied on for management or storage of the cryptographic key, by:

receiving a request from the second HSM to associate the cryptographic key with the second HSM, the request having associated identification information for a requester of the cryptographic key;

verifying an entitlement of the requester to the cryptographic key by the first HSM, wherein the entitlement of the requester is verified based on the identification information for the requester;

responsive to the verification by the first HSM, generating a new record for storage in the blockchain, the new record associating the cryptographic key with the second HSM and being validated by the miner components;

further responsive to the verification by the first HSM, securely and non-repudiatively transferring the cryptographic key from the first HSM to the second HSM;

verifying that the cryptographic key is associated with the second HSM in the blockchain; and

responsive to the verification that the cryptographic key is associated with the second HSM, transferring the cryptographic key from the second HSM to the requester of the cryptographic key.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the computer program code, when loaded into the computer system and executed thereon, cause the computer system to provide access to the cryptographic key further including by:

further responsive to the verification of the entitlement of the requester, effecting a change to the second HSM for providing the cryptographic key, the change being relative to the resource cost of ownership of the cryptographic key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2019
From: DANIEL, JOSHUA
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 051204/0625 →
Priority Claims (1)
EP 17175392 · Jun 12, 2017 · regional
Continuity (1)
Related Publication 20210083856A1 · Mar 18, 2021
References Cited (120)
US 6535493B1 · Lee et al. · 2003 [cited by applicant]
US 8151322B2 · Chen et al. · 2012 [cited by applicant]
US 8590057B1 · Mayblum et al. · 2013 [cited by applicant]
US 9807106B2 · Daniel · 2017 [cited by applicant]
US 10015671B2 · Zaifuddin et al. · 2018 [cited by applicant]
US 10082719B2 · Xie · 2018 [cited by applicant]
US 10534913B2 · Daniel · 2020 [cited by applicant]
US 10839378B1 · Srinivasan et al. · 2020 [cited by applicant]
US 11122500B2 · Salgueiro et al. · 2021 [cited by applicant]
US 11489693B2 · Daniel et al. · 2022 [cited by applicant]
US 20040213260A1 · Leung et al. · 2004 [cited by applicant]
US 20040250066A1 · Di Luoffo · 2004 [cited by examiner]
US 20050009517A1 · Maes · 2005 [cited by applicant]
US 20090061859A1 · Bengtsson · 2009 [cited by applicant]
US 20110130117A1 · Fan et al. · 2011 [cited by applicant]
US 20120044862A1 · Chen et al. · 2012 [cited by applicant]
US 20130044733A1 · Jang · 2013 [cited by applicant]
US 20140323088A1 · Hsieh · 2014 [cited by applicant]
US 20140355520A1 · Wallis · 2014 [cited by applicant]
US 20140355564A1 · Cherian et al. · 2014 [cited by applicant]
US 20140368601A1 · Decharms · 2014 [cited by applicant]
US 20150040195A1 · Park et al. · 2015 [cited by applicant]
US 20150181424A1 · Hardy · 2015 [cited by applicant]
US 20150195713A1 · Canpolat et al. · 2015 [cited by applicant]
US 20150373029A1 · Evenden et al. · 2015 [cited by applicant]
US 20160142911A1 · Kreiner et al. · 2016 [cited by applicant]
US 20160180338A1 · Androulaki et al. · 2016 [cited by applicant]
US 20160183081A1 · Flores Cuadrado et al. · 2016 [cited by applicant]
US 20160261690A1 · Ford · 2016 [cited by applicant]
US 20160364787A1 · Walker · 2016 [cited by examiner]
US 20170053460A1 · Hauser · 2017 [cited by examiner]
US 20170124534A1 · Savolainen · 2017 [cited by applicant]
US 20170132630A1 · Castinado et al. · 2017 [cited by applicant]
US 20170206523A1 · Goeringer et al. · 2017 [cited by applicant]
US 20180025166A1 · Daniel · 2018 [cited by applicant]
US 20180049019A1 · Haran et al. · 2018 [cited by applicant]
US 20180197173A1 · Durvasula et al. · 2018 [cited by applicant]
US 20180225466A1 · Ducatel · 2018 [cited by examiner]
US 20180254894A1 · Arnold · 2018 [cited by examiner]
US 20180262341A1 · Cheng · 2018 [cited by examiner]
US 20180278423A1 · Bianzino · 2018 [cited by examiner]
US 20180285585A1 · Daniel · 2018 [cited by applicant]
US 20180322259A1 · Solow · 2018 [cited by examiner]
US 20190108364A1 · Roennow et al. · 2019 [cited by applicant]
US 20190130394A1 · Stollman · 2019 [cited by examiner]
US 20190230491A1 · Yu et al. · 2019 [cited by applicant]
US 20190253409A1 · Spencer · 2019 [cited by applicant]
US 20190386832A1 · Palyutina et al. · 2019 [cited by applicant]
US 20200007316A1 · Krishnamacharya et al. · 2020 [cited by applicant]
US 20200178075A1 · Daniel · 2020 [cited by applicant]
US 20200242603A1 · Salkintzis · 2020 [cited by applicant]
US 20200380090A1 · Marion · 2020 [cited by examiner]
US 20210014060A1 · Georgiadis · 2021 [cited by examiner]
CN 107018432 · 2017 [cited by examiner]
EP 2894890A1 · 2015 [cited by applicant]
GB 2540976A · 2017 [cited by applicant]
GB 2540977A · 2017 [cited by applicant]
WO WO2005119606A1 · 2005 [cited by examiner]
WO WO2006069312A2 · 2006 [cited by examiner]
WO WO2016078382A1 · 2016 [cited by examiner]
WO WO2016128491A1 · 2016 [cited by applicant]
WO WO2017021153 · 2017 [cited by applicant]
WO WO2017021154 · 2017 [cited by applicant]
WO WO2017021155 · 2017 [cited by applicant]
WO WO2017167547 · 2017 [cited by applicant]
WO WO2017167548 · 2017 [cited by applicant]
WO WO2017167549 · 2017 [cited by applicant]
WO WO2017184160A1 · 2017 [cited by applicant]
WO WO2018125989A2 · 2018 [cited by applicant]
WO WO2018178026 · 2018 [cited by applicant]
WO WO2018178034 · 2018 [cited by applicant]
WO WO2018178035 · 2018 [cited by applicant]
WO WO2018206374 · 2018 [cited by applicant]
WO WO2018206405 · 2018 [cited by applicant]
WO WO2018206406 · 2018 [cited by applicant]
WO WO2018206407 · 2018 [cited by applicant]
WO WO2018206408 · 2018 [cited by applicant]
WO WO2018228973A1 · 2018 [cited by applicant]
WO WO2018228974A1 · 2018 [cited by applicant]
Bitfury Group Limited “Bitfury: On Blockchain Auditability” [online] White Paper, Nov. 14, 2016 [retrieved Jun. 19, 2020]. Retrieved from the Internet: URL: https://bitfury.com/content/downloads/bitfury_white_paper_on_b… [cited by examiner]
Selmanovic, Demir “Cryptocurrency for Dummies: Bitcoin and Beyond” [online] Toptal, Aug. 7, 2015 [retrieved Aug. 15, 2024]. Retrieved from the Internet: URL: https://www.toptal.com/bitcoin/cryptocurrency-for-dummies-bit… [cited by examiner]
Antonopoulos A M., “Mastering Bitcoin-Unlocking Digital Crypto-Currencies,” Apr. 2014, Early Release Raw & Unedited, ISBN: 978-1-449-37404-4; retrieved from: https://unglueitfiles.s3.amazonaws.com/ebf/05db7df4f31840f0a8… [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Great Britain Application No. 1709275.0, mailed on Dec. 1, 2017, 8 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Great Britain Application No. 1809489.6, mailed on Dec. 10, 2018, 8 pages. [cited by applicant]
Deloitte, “Blockchain @ Telco How Block Chain Can Impact The Telecommunications Industry and Its Relevance to The C-Suite Introduction to Block Chain,” retrieved from https://www2.deloitte.com/content/dam/Deloitte/za/Do… [cited by applicant]
Dorri A., et al., “Blockchain for IoT Security and Privacy: The Case Study of a Smart Home,” 2nd IEEE Percom Workshops, 2017, 7 pages. [cited by applicant]
Extended European Search Report for Application No. 17175392.4, mailed on Nov. 29, 2017, 8 pages. [cited by applicant]
Extended European Search Report for Application No. 17175393.2, mailed on Dec. 4, 2017, 8 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2018/065303, mailed on Dec. 26, 2019, 8 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2018/065233, mailed on Dec. 26, 2019, 10 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2018/065235, mailed on Dec. 26, 2019, 8 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2018/065234, mailed Dec. 26, 2019, 8 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2018/065302, mailed on Dec. 26, 2019, 7 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2018/065233, mailed on Jul. 10, 2018, 12 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2018/065235, mailed on Sep. 3, 2018, 9 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2018/065302, mailed on Aug. 3, 2018, 8 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2018/065303, mailed on Aug. 6, 2018, 11 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2018/065234, mailed Sep. 3, 2018, 9 pages. [cited by applicant]
Jover R.P., et al., “dHSS—Distributed Peer-to-Peer Implementation of The LTE HSS Based on The Bitcoin/Namecoin Architecture,” 2016 IEEE International Conference on Communications Workshops (ICC), IEEE, May 23, 2016, pp.… [cited by applicant]
Sanda T., et al., “Proposal of New Authentication Method In Wi-Fi Access Using Bitcoin 2.0,” 2016 IEEE 5th Global Conference on Consumer Electronics, IEEE, Oct. 11, 2016, pp. 1-5. [cited by applicant]
Search Report under Section 17 for Great Britain Application No. 1709276.8, mailed on May 8, 2018, 4 pages. [cited by applicant]
Application and File History for U.S. Appl. No. 16/620,260, filed Dec. 6, 2019, Inventor: Daniel. [cited by applicant]
Application and File History for U.S. Appl. No. 16/620,277, filed Dec. 6, 2019, Inventor: Daniel. [cited by applicant]
Application and File History for U.S. Appl. No. 16/620,328, filed Dec. 6, 2019, Inventor: Daniel. [cited by applicant]
Application and File History for U.S. Appl. No. 16/620,355, filed Dec. 6, 2019, Inventor: Daniel. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) mailed Nov. 7, 2017 for Great Britain Application No. 1709272.7, 8 pages. [cited by applicant]
Combined Search and Examination Report under sections 17 & 18(3) for Great Britain Application No. 1709273.5, mailed on Nov. 7, 2017, 8 pages. [cited by applicant]
Combined Search and Examination Report under sections 17 & 18(3) for Great Britain Application No. 1709274.3, mailed on Oct. 31, 2017, 8 pages. [cited by applicant]
Communication pursuant to Article 94(3) EPC for Application No. 18728662.0, mailed on Jan. 26, 2021, 6 pages. [cited by applicant]
Communication pursuant to Article 94(3) EPC For European Application No. 18728429.4, mailed on Feb. 4, 2021, 7 pages. [cited by applicant]
Communication pursuant to Article 94(3) EPC For European Application No. 18728430.2, mailed on Feb. 4, 2021, 7 pages. [cited by applicant]
Communication pursuant to Article 94(3) EPC For European Application No. 18728663.8, mailed on Jan. 26, 2021, 7 pages. [cited by applicant]
Examination Report under Section 18(3) for Great Britain Application No. 1709275.0, mailed on Jul. 8, 2020, 5 pages. [cited by applicant]
Extended European Search Report for Application No. 17175391.6, mailed on Nov. 14, 2017, 8 pages. [cited by applicant]
Extended European Search Report for Application No. 17175394.0, mailed on Nov. 14, 2017, 8 pages. [cited by applicant]
Extended European Search Report for Application No. 17175395.7, mailed on Aug. 10, 2017, 11 pages. [cited by applicant]
Noting of Loss of Rights Pursuant to Rule 112(1) EPC for 18728428.6, mailed on Aug. 21, 2020, 1 page. [cited by applicant]
Application and File History for U.S. Appl. No. 16/620,241, filed Dec. 6, 2019, Inventor: Daniel. [cited by applicant]
Communication pursuant to Article 94(3) EPC for Application No. 18728662.0, mailed on Oct. 28, 2021, 6 pages. [cited by applicant]
Communication pursuant to Article 94(3) EPC for Application No. 18728430.2 mailed on Apr. 21, 2022, 6 pages. [cited by applicant]